CVE-2023-23588
A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC647D (All versions), SIMATIC IPC647E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC847D (All versions), SIMATIC IPC847E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows). The Adaptec Maxview application on affected devices is using a non-unique TLS certificate across installations to protect the communication from the local browser to the local application. A local attacker may use this key to decrypt intercepted local traffic between the browser and the application and could perform a man-in-the-middle attack in order to modify data in transit.
EPSS 0.06% · 19.1th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| siemens | simatic_ipc847d_firmware | |
| Siemens | SIMATIC IPC847D | * |
| Siemens | SIMATIC IPC1047E | All versions with maxView Storage Manager < 4.09.00.25611 on Windows |
| Siemens | SIMATIC IPC647D | All versions |
| Siemens | SIMATIC IPC647E | All versions with maxView Storage Manager < 4.09.00.25611 on Windows |
| microchip | maxview_storage_manager | 0, 0 |
| Siemens | SIMATIC IPC1047 | All versions |
| siemens | simatic_ipc1047_firmware | |
| siemens | simatic_ipc647d_firmware | |
| Siemens | SIMATIC IPC847E | All versions with maxView Storage Manager < 4.09.00.25611 on Windows |
Exploit Intelligence
Timeline
- Apr 11, 2023 CVE Published
- Apr 11, 2023 EPSS Score
- May 19, 2023 EPSS Score
- Jun 26, 2023 EPSS Score
- Aug 2, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
- Oct 17, 2023 EPSS Score
- Nov 24, 2023 EPSS Score
- Dec 31, 2023 EPSS Score
- Feb 7, 2024 EPSS Score
- Mar 16, 2024 EPSS Score
- Apr 23, 2024 EPSS Score
References
- https://cert-portal.siemens.com/productcert/html/ssa-699404.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-479249.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-572164.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-691715.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-511182.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-566905.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-642810.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-603476.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-813746.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-629917.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-558014.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-322980.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-116924.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-632164.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-472454.html advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-511182.pdf url
- https://nvd.nist.gov/vuln/detail/CVE-2023-23588 advisory